• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 579
  • Last Modified:

Active Directory - File Shares User Rights

Hi,

we have a "File Server" running on windows server 2003 R2 in our domain with 1,2 TB of user data... :)
With over thousands of folders and subfolders. And right now we have no way of knowing which user have what right to what folder (or subfolder)...
My question is, is there any kind of program, script, or some another way to see which user has what right to a folder on that server?
For example, we have folder "Production" with 10 subfolders, and we want to know what right does a user "John" have for that folder and subfolders.

Hope somebody knows how to solve this cause I am out of ideas :)
Thanks
0
Sebastianpervan
Asked:
Sebastianpervan
  • 3
  • 2
  • 2
  • +2
2 Solutions
 
gaurav2rawatCommented:
You could use ad ntfs permissions analyzer which gives all the shared and ntfs permission
her is the link, good luck.

http://www.solarwinds.com/products/freetools/permissions_analyzer_for_active_directory/
0
 
SebastianpervanAuthor Commented:
Hi gaurav2rawat,

thanks for the suggestion, I actually already tried it, but unfortunately is only shows permissions for one folder (that you choose) not the subfolders in it.

I am really stuck on this one... :/
Because I would like to list for all the the users all the folders that they can access. And then to see which users have too much rights and acess.
0
 
gaurav2rawatCommented:
Hello

You'll have to manually check it for all the folders as even other tools that are available doesn't really tells the permission for subfolders. You could try AD Manager plus but I doubt even that'll provide such granularity.
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
Leon FesterSenior Solutions ArchitectCommented:
Our auditors frequently use dumpsec to get permissions from servers:
http://www.systemtools.com/somarsoft/?somarsoft.com

Another tool from Microsoft is Calcs:
http://ss64.com/nt/cacls.html
0
 
PberSolutions ArchitectCommented:
A free tool might be tough.  As dvt_localboy mentioned auditors typically use dumpsec and troll through the output.

At one time we used this: http://www.quest.com/enterprisesecurityreporter/ (it was still Scriptlogic at the time).  It will collect all your security from all your folders/files, etc and place them in a database that can then be queried any which way you like.  We used it for duplicate group cleanup.
0
 
SebastianpervanAuthor Commented:
Thank You all for your replies, I will test these applications in these few days and get back to you!
:)

Regards,
Sebastian
0
 
Leon FesterSenior Solutions ArchitectCommented:
Last time I checked, dumpsec was free and pretty easy to use.
It has many builtin queries and reports, available at a click.
0
 
Venugopal NCommented:
Also you can use Varonis from which you can generate the report for all kind of needs.Also varonis it provides automated unstructured data protection and management ( i.e.., the data access can be managed by the data owners itself).But the hard part is it not free of cost.
0
 
SebastianpervanAuthor Commented:
Thanks everyone for the help, I've distributed points based on the speed of the posts and applications cost :)
Both application will do the trick!

Thanks,
Sebastian
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Cloud Class® Course: Certified Penetration Testing

This CPTE Certified Penetration Testing Engineer course covers everything you need to know about becoming a Certified Penetration Testing Engineer. Career Path: Professional roles include Ethical Hackers, Security Consultants, System Administrators, and Chief Security Officers.

  • 3
  • 2
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now